CVE Published: 11/02/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: SearchWidget Status : PUBLISHED
CVE-2022-24923 Description
Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.
Metrics
CVSS Version: 3.1 |
Base Score: 4 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N